Update Google Chrome now — important zero-day flaw exposed

Google Chrome
(Image credit: Shutterstock)

Google has pushed out a new version of Chrome for Windows, macOS and Linux to patch a zero-day flaw that is being actively exploited in the wild.

The update takes Chrome to version number 88.0.4324.150. You can check where your Chrome installation is by going to Settings (the three stacked dots in the upper right corner) > Help > About Google Chrome. Opening that page will force Chrome to update if it hasn't already.

Other browsers that share Chrome's code may not have caught up yet. At the time of this writing, Brave was still stuck on the previous version. Microsoft Edge had an update ready, but because its version-numbering scheme is different, we can't quite tell if it fixes the Chrome flaw.

Google didn't provide many details about the flaw being fixed in its Chrome release bulletin, but did say it addresses a "heap buffer overflow in V8," Chrome's JavaScript engine. That means the flaw lets a process overflow the memory limitations for JavaScript processes and then inject code into them.

The flaw has been given the catalog number CVE-2021-21148, and Google said it was "aware of reports that an exploit ... exists in the wild." 

The flaw was reported to Google by an independent security researcher named Mattias Buelens on Jan. 24. That was the day before Google disclosed a North Korean espionage campaign against security researchers that used flaws in Chrome and Internet Explorer, so there may be some connection.

Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Latest in Browsers
iPhone 16 Pro Max shown in hand
Your iPhone has a custom voice command feature — here's how to use it
iPhone 16 Pro Max shown in hand
You can change your iPhone's default browser — here's how
Google Chrome on Android
How to stop your personal data from appearing in Google searches
Opera Air
I just tested the world’s first mindful browser — it’s calmly convinced me to ditch Google Chrome
A photo of the Google Chrome logo on a white background, displayed on the screen of a large MacBook Pro which is situated on a table with green foliage behind.
Google Chrome just got three new modes — and it's a game changer for performance
Google Calendar app on iPhone
Google Calendar just got the dark mode we’ve been waiting for — here’s how to activate it
Latest in News
iPhone 16 with Apple Intelligence logo for iOS 18.1
iOS 18.4: All the newest Apple Intelligence features coming to your iPhone
Maria Debska in "Just One Look" now streaming on Netflix
3 best Netflix shows in March you haven't watched yet
Split image featuring the Galaxy S25 Edge (left) and Galaxy S25 Ultra (right)
Samsung Galaxy S25 Edge just tipped for two Galaxy S25 Ultra-level features
Wolfenstein: The Old Blood
Amazon is giving away a ton of free games for its Big Spring Sale — here’s how to claim yours
A TV with the Netflix logo sits behind a hand holding a remote
Netflix is rolling out a big video quality upgrade — what you need to know
Choi Hyun-Wook, Hong Kyung, and Park Ji-hoon in "Weak Hero Class 1" now streaming on Netflix
This action-packed K-drama is now streaming on Netflix — and now’s the time to binge-watch before season 2